An issue was discovered in SeaCMS 6.64. XSS exists in admindatarelate.php via the time or maxHit parameter in a dorandomset action.
In SeaCMS v6.6.4, there is stored XSS via the member.php?action=chgpwdsubmit email parameter during a password change, as demonstrated by a data: URL in an OBJECT element.
In SeaCMS v6.64, there is SQL injection via the adminmakehtml.php topic parameter because of mishandling in include/mkhtml.func.php.
SeaCMS 6.64 and 7.2 allows remote attackers to delete arbitrary files via the filedir parameter.
An issue was discovered in SeaCMS 6.64. XSS exists in adminvideo.php via the action, area, type, yuyan, jqtype, visunion, vrecycled, vismoney, or vispsd parameter.
SeaCMS 6.64 allows arbitrary directory listing via upload/admin/admintemplate.php?path=../templets/../../ requests.
SeaCMS 6.64 allows SQL Injection via the upload/admin/adminvideo.php order parameter.